Edit report at https://bugs.php.net/bug.php?id=68921&edit=1
ID: 68921
User updated by: public at grik dot net
Reported by: public at grik dot net
Summary: segfault
-Status: No Feedback
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Cent OS 6
PHP Version: 5.6.5
Block user comment: N
Private report: N
New Comment:
segfault is reproduced when an empty Content-Type header and when no data is provided with POST
request,
the content of the script does not matter, php file can be empty
$ curl -d '' -H 'Content-Type:' http://testsite.local/t.php
<html>
<head><title>502 Bad Gateway</title></head>
<body bgcolor="white">
<center><h1>502 Bad Gateway</h1></center>
$ sudo tail /var/log/messages
Mar 3 16:53:30 hotelfm kernel: php-fpm[15374]: segfault at 0 ip 0844e25d sp bfb09f80 error 4 in
php-fpm[8048000+ace000]
Previous Comments:
------------------------------------------------------------------------
[2015-02-08 04:22:15] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2015-01-27 15:04:51] laruence@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
------------------------------------------------------------------------
[2015-01-27 14:37:15] public at grik dot net
Description:
------------
Segfault after upgrade from 5.5.5 to 5.6.5
Test script:
---------------
I don't have an exact reproducable script atm, can create it if required.
Actual result:
--------------
Core was generated by `php-fpm: pool www
'.
Program terminated with signal 11, Segmentation fault.
#0 0x0844e25d in _zval_dtor_func (zvalue=0xb771b098,
__zend_filename=0x89136cc "/usr/src/php-5.6.5/Zend/zend_execute.h", __zend_lineno=79)
at /usr/src/php-5.6.5/Zend/zend_variables.c:36
36 CHECK_ZVAL_STRING_REL(zvalue);
Missing separate debuginfos, use: debuginfo-install ImageMagick-6.5.4.7-7.el6_5.i686
bzip2-libs-1.0.5-7.el6_0.i686 cyrus -sasl-lib-2.1.23-15.el6_6.1.i686
expat-2.0.1-11.el6_2.i686 fontconfig-2.8.0-5.el6.i686 freetype-2.3.11-14.el6_3.1.i686 g
libc-2.12-1.149.el6_6.4.i686 keyutils-libs-1.4-5.el6.i686
krb5-libs-1.10.3-33.el6.i686 lcms-libs-1.19-1.el6.i686 libICE-
1.0.6-1.el6.i686 libSM-1.2.1-2.el6.i686 libX11-1.6.0-2.2.el6.i686 libXau-1.0.6-4.el6.i686
libXext-1.3.2-2.1.el6.i686 lib Xt-1.1.4-6.1.el6.i686
libcom_err-1.41.12-21.el6.i686 libcurl-7.19.7-40.el6_6.3.i686 libgcc-4.4.7-11.el6.i686 libgomp-4.4
.7-11.el6.i686 libidn-1.18-2.el6.i686 libjpeg-turbo-1.2.1-3.el6_5.i686
libpng-1.2.49-1.el6_2.i686 libselinux-2.0.94-5.8. el6.i686
libssh2-1.4.2-1.el6.i686 libtiff-3.9.4-10.el6_5.i686 libtool-l!
tdl-2.2.6-15.5.el6.i686 libuuid-2.17.2-12.18.el6. i686
libxcb-1.9.1-2.el6.i686 libxml2-2.7.6-17.el6_6.1.i686 nspr-4.10.6-1.el6_5.i686
nss-3.16.2.3-3.el6_6.i686 nss-softok n-freebl-3.14.3-18.el6_6.i686
nss-util-3.16.2.3-2.el6_6.i686 openldap-2.4.39-8.el6.i686 openssl-1.0.1e-30.el6_6.4.i686 p
ostgresql93-libs-9.3.5-1PGDG.rhel6.i686 zlib-1.2.3-29.el6.i686
(gdb) bt
#0 0x0844e25d in _zval_dtor_func (zvalue=0xb771b098,
__zend_filename=0x89136cc "/usr/src/php-5.6.5/Zend/zend_execute.h", __zend_lineno=79)
at /usr/src/php-5.6.5/Zend/zend_variables.c:36
#1 0x0843daeb in _zval_dtor (zvalue=0xb771b098, __zend_filename=0x89136cc
"/usr/src/php-5.6.5/Zend/zend_execute.h",
__zend_lineno=79) at /usr/src/php-5.6.5/Zend/zend_variables.h:35
#2 0x0843db98 in i_zval_ptr_dtor (zval_ptr=0xb771b098,
__zend_filename=0x89157fc "/usr/src/php-5.6.5/Zend/zend_variables.c",
__zend_lineno=188)
at /usr/src/php-5.6.5/Zend/zend_execute.h:79
#3 0x0843e863 in _zval_ptr_dtor (zval_ptr=0xb771b210,
__zend_filename=0x89157fc "/usr/src/php-5.6.5/Zend/zend_variables.c",
__zend_lineno=188)
at /usr/src/php-5.6.5/Zend/zend_execute_API.c:424
#4 0x0844e6e7 in _zval_ptr_dtor_wrapper (zval_ptr=0xb771b210) at
/usr/src/php-5.6.5/Zend/zend_variables.c:188
#5 0x0845e96f in i_zend_hash_bucket_delete (ht=0x8b3673c, p=0xb771b204) at
/usr/src/php-5.6.5/Zend/zend_hash.c:182
#6 0x0845ea35 in zend_hash_bucket_delete (ht=0x8b3673c, p=0xb771b204) at
/usr/src/php-5.6.5/Zend/zend_hash.c:192
#7 0x08460447 in zend_hash_graceful_reverse_destroy (ht=0x8b3673c) at
/usr/src/php-5.6.5/Zend/zend_hash.c:613
#8 0x0843e34b in shutdown_executor () at /usr/src/php-5.6.5/Zend/zend_execute_API.c:244
#9 0x08450451 in zend_deactivate () at /usr/src/php-5.6.5/Zend/zend.c:960
#10 0x083d3240 in php_request_shutdown (dummy=0x0) at /usr/src/php-5.6.5/main/main.c:1884
#11 0x084f9dc8 in main (argc=6, argv=0xbfdbf114) at /usr/src/php-5.6.5/sapi/fpm/fpm/fpm_main.c:1988
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68921&edit=1